App-V Virtual Environment in SCCM

In a Microsoft Application Virtualization (App-V) virtual environment in System Center Configuration Manager (Configuration Manager), deployed virtual applications can share the same file system and registry on client Windows PCs. Unlike standard virtual applications, these applications can share data with each other. 

Virtual environments are created or modified on client PCs when the application is installed or when clients next evaluate their installed applications. You can order these applications so that when multiple applications try to modify a file system or registry value, the application with the highest order takes priority.

In the Configuration Manager console, choose Software Library > Application Management > App-V Virtual Environments.

On the Home tab, in the Create group, choose Create Virtual Environment.


In the Create Virtual Environment dialog box, enter the following information:
Name. Enter a unique name for the virtual environment (maximum 128 characters).
Description. (Optional) Enter a description for the virtual environment
To add a new deployment type to the virtual environment, choose Add. You must add at least one deployment type.
In the Add Applications dialog box, specify a Group name (maximum 128 characters). You'll use this name to refer to the group of applications that you add to the virtual environment.
Choose Add, select the App-V 5 applications and deployment types that you want to add to the group, and then choose OK.
In the Add Applications dialog box, you can select Increase Order or Decrease Order to set the application that takes priority if multiple applications attempt to modify file system or registry settings in the same virtual environment.
To return to the Create Virtual Environment dialog box, choose OK.

When you're done adding groups, choose OK to create the virtual environment. The new virtual environment is displayed in the App-V Virtual Environments node of the Configuration Manager console. You can monitor the status of your virtual environments by using the App-V Virtual Environment Status report.
[!NOTE]
The virtual environment is added or modified on client PCs when the application is installed or when the client next evaluates installed applications.

Application Dependencies in SCCM

A new feature in CM 2012 is the ability to set dependencies on applications. This is something that I have been waiting for and it works really well.
For example this is my deployment for AX 2012 Client.
In this scenario I needed to create 4 different dependencies that would all be installed, this is done by pressing “Add” and then adding a dependency, if you add 2 dependencies under the same group it will be “this OR that” but if you add them in different groups it will be “this AND that”.
You can for example have one group and add different versions of Visual C++ Redistributable if the application does not require the latest version it will check if any of those versions are installed, if any of those versions are installed it will skip it.
If you add 2 dependencies under the same group you can also set priority, if none of the dependencies are installed the application with the highest priority is the first one to be installed, the best way here is to only check “Auto Install” on the application you want to install if the device is not satisfying.
A dependency doesn’t have to be something that the application you are installing requires it can be anything.
I created a bunch of applications in a folder I call “Pre Reqs\Microsoft” with the most common pre requisites like SQL Native Client etc etc, stuff that I can use over and over again.
When you deploy an application that have dependencies linked to it the SCCM Client will check what decencies is already installed, if none are installed it will automatically download them and install.
This also works when doing it via task sequence.
If you check Software Center you will see the number of components it downloads if you have 4 dependencies and 1 is installed it will say downloading 4 components (3 dependencies and the program itself)
One thing to keep in mind is that if a dependency fails to install the whole deployment fails. You can see what dependency failed under deployment monitoring. I had one case where my C++ 2010 was an older version and the deployment failed because a newer version was already installed on the computer.

Windows Updates Scan Issue on Client machine

As most of administrator are suffering from the issue now to fix the WSUS scan error on the client machine, have created a powershell script to fix most of the error code from the client machine.

Below script will Fix below error code from the WUAHandler.log and Windowsupdate.log file form the client machine.

SCCMReport Last scan error code   WUAHandler     Log error code   Error Description
-2147467259   0x80004005 E_Fail  
-2147467262 0x80004002 E_NOINTERFACE No such interface supported 
-2147024891 0x80070005 ERROR_ACCESS_DENIED or E_ACCESS_DENIED The authentication method is not supported. - CoCreateInstance(IBackgroundCopyManager) fails with E_ACCESSDENIED (0x80070005) in this condition 
-2147024883 0x8007000D The data is invalid.* The data is invalid.* 
-2147023838 0x80070422 ERROR_SERVICE_DISABLED The service cannot be started. If BITS service is disabled by the Administrator, then this error will be seen. 
-2147012894 0x80072EE2 ERROR_INTERNET_TIMEOUT The request has timed out.
-2145107961 0x80244007 WU_E_PT_SOAPCLIENT_SOAPFAULT error codes.Same as SOAPCLIENT_SOAPFAULT - SOAP client failed because there was a SOAP fault for reasons of WU_E_PT_SOAP_* 
-2145107952 0x80244010 WU_E_PT_EXCEEDED_MAX_SERVER_TRIPS The number of round trips to the server exceeded the maximum limit. 
Copy the below content to a file and name it as WSUS_Fix.ps1 and run it on the machine where your are facing the error.

$ErrorActionPreference = "SilentlyContinue"
[string] $systems= "Localhost"
If ($Error) {
$Error.Clear()
}

## Log Files location and write log function
$Logfile = "C:\Windows\Temp\$(gc env:computername).log"
Function LogWrite
{
   Param ([string]$logstring)
   Add-content $Logfile -value $logstring
}

## Stop WUAUSERV service
$ServStat = (Get-Service "WUAUSERV").Status
$Check = [String]::Compare($ServStat, "Running", $True)
If ($Check -EQ 0) {
LogWrite "`n"
LogWrite -ForegroundColor Yellow "`tStopping Automatic Update Service ..."
Stop-Service "WUAUSERV" | Out-Null
LogWrite -ForegroundColor Yellow "`tAutomatic Update Service Stopped"
}

## Delete the SUSClientID
$Res = (Get-ItemProperty -Path "HKLM:\Software\Microsoft\Windows\CurrentVersion\WindowsUpdate" -Name SUSClientID).SUSClientID
LogWrite -ForegroundColor Yellow "tRe-Configuring Windows Update Settings ..."
Remove-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate" -Name "SusClientID"

## Rename The SoftwareDistribution Folder

LogWrite "Starting to Rename The SoftwareDistribution Folder"
LogWrite "Checking if OLD_SoftwareDistribution folder exists if found will remove it.."
If (Test-Path "C:\Windows\OLD_SoftwareDistribution") {
LogWrite "OLD_SoftwareDistribution folder exists will start deleting the folder..."
Remove-Item -Path "C:\Windows\OLD_SoftwareDistribution" -Force -Recurse
LogWrite "OLD_SoftwareDistribution folder deleted successfully!"
}
If (Test-Path "C:\Windows\SoftwareDistribution") {
LogWrite "SoftwareDistribution folder exists will start deleting the folder..."
Rename-Item "C:\Windows\SoftwareDistribution" "OLD_SoftwareDistribution"
LogWrite "SoftwareDistribution folder deleted successfully!"
}

## Rename The Registry.Pol Files
If (Test-Path "C:\Windows\System32\GroupPolicy\Machine") {
LogWrite "Registry.pol file exists will start deleting the file..."
Remove-Item -Path "C:\Windows\System32\GroupPolicy\Machine\OLD_Registry.pol" -Force -Recurse
LogWrite "Registry.pol file deleted successfully!"
}
If (Test-Path "C:\Windows\System32\GroupPolicy\Machine") {
LogWrite "Registry.pol exists will start renaming the file..."
Rename-Item "C:\Windows\System32\GroupPolicy\Machine\Registry.pol" "OLD_Registry.pol"
LogWrite "Registry.pol Rename successfully!"
}

## Register all the DLL files of WUSU.
LogWrite "Started to Register all the DLL files of WUSU..."
regsvr32.exe /s "c:\Windows\system32\Actxprxy.dll"
regsvr32.exe /s "c:\Windows\system32\Atl.dll"
regsvr32.exe /s "c:\Windows\system32\Browseui.dll"
regsvr32.exe /s "c:\Windows\system32\cryptdlg.dll"
regsvr32.exe /s "c:\Windows\system32\dssenh.dll"
regsvr32.exe /s "c:\Windows\system32\gpkcsp.dll"
regsvr32.exe /s "c:\Windows\system32\initpki.dll"
regsvr32.exe /s "c:\Windows\system32\jscript.dll"
regsvr32.exe /s "c:\Windows\system32\Mshtml.dll"
regsvr32.exe /s "c:\Windows\system32\Msjava.dll"
regsvr32.exe /s "c:\Windows\system32\Mssip32.dll"
regsvr32.exe /s "c:\Windows\system32\msxml.dll"
regsvr32.exe /s "c:\Windows\system32\msxml2.dll"
regsvr32.exe /s "c:\Windows\system32\Msxml3.dll"
regsvr32.exe /s "c:\Windows\system32\Oleaut32.dll"
regsvr32.exe /s "c:\Windows\system32\rsaenh.dll"
regsvr32.exe /s "c:\Windows\system32\sccbase.dll"
regsvr32.exe /s "c:\Windows\system32\shdocvw.dll"
regsvr32.exe /s "c:\Windows\system32\shell32.dll"
regsvr32.exe /s "c:\Windows\system32\slbcsp.dll"
regsvr32.exe /s "c:\Windows\system32\softpub.dll"
regsvr32.exe /s "c:\Windows\system32\Urlmon.dll"
regsvr32.exe /s "c:\Windows\system32\vbscript.dll"
regsvr32.exe /s "c:\Windows\system32\wintrust.dll"
regsvr32.exe /s "c:\Windows\system32\wuapi.dll"
regsvr32.exe /s "c:\Windows\system32\wuaueng.dll"
regsvr32.exe /s "c:\Windows\system32\wuaueng1.dll"
regsvr32.exe /s "c:\Windows\system32\wucltui.dll"
regsvr32.exe /s "c:\Windows\system32\wups.dll"
regsvr32.exe /s "c:\Windows\system32\wups2.dll"
regsvr32.exe /s "c:\Windows\system32\wuweb.dll"
LogWrite "DLL registration completed successfully!"

## Start WUAUSERV service
Start-Service "WUAUSERV"
Invoke-Command -Script {wuauclt /resetauthorization /detectnow} | Out-Null
Invoke-Command -Script {wuauclt /reportnow} | Out-Null
LogWrite -ForegroundColor Yellow "`tExecution Complete."
LogWrite "`n"

#Group Policy Update
LogWrite "Requesting for Policy Changes..."
gpupdate /Force

## Add UseWUServer DWord Value to 1

$RegKey = “HKLM:\Software\Policies\Microsoft\Windows\WindowsUpdate\AU”
if (-Not(Test-Path “$RegKey”)) {
LogWrite "checking if UseWUServer Registry key exists if not will write the registry value...."
New-Item -Path “$($RegKey.TrimEnd($RegKey.Split(‘\’)[-1]))” -Name “$($RegKey.Split(‘\’)[-1])” -Force | Out-Null
}
Set-ItemProperty -Path “$RegKey” -Name “UseWUServer” -Type Dword -Value “1”
LogWrite "Adding UseWUServer Registry key value completed successfully!"

$RegKey = “HKLM:\Software\Policies\Microsoft\Windows\WindowsUpdate”
if (-Not(Test-Path “$RegKey”)) {
LogWrite "checking if UseWUServer Registry key exists if not will write the registry value...."
New-Item -Path “$($RegKey.TrimEnd($RegKey.Split(‘\’)[-1]))” -Name “$($RegKey.Split(‘\’)[-1])” -Force | Out-Null
}
Set-ItemProperty -Path “$RegKey” -Name “WUServer” -Type String -Value “http://<WSUS.SERVER>:8530”
Set-ItemProperty -Path “$RegKey” -Name “WUStatusServer” -Type String -Value “http://<WSUS.SERVER>:8530”
LogWrite "Adding WUServer and WUStatusServer Registry value completed successfully!"

## Start Machine Policy Retrivel and Evaluation Cycle
LogWrite "Start Machine Policy Retrivel and Evaluation Cycle..."
Invoke-WmiMethod -ComputerName $systems -Namespace root\ccm -Class sms_client -Name TriggerSchedule -ArgumentList '{00000000-0000-0000-0000-000000000021}' -ErrorAction Stop
LogWrite "Sleeping for 150 Seconds..."
Start-Sleep -Seconds 150

## Start Software Update Scan Cycle
LogWrite "Start Software Update Scan Cycle..."
Invoke-WmiMethod -ComputerName $systems -Namespace root\ccm -Class sms_client -Name TriggerSchedule -ArgumentList '{00000000-0000-0000-0000-000000000113}' -ErrorAction Stop
LogWrite "Sleeping for 150 Seconds..."
Start-Sleep -Seconds 150

## Start Software Update Deployment Evaluation Cycle
LogWrite "Start Software Update Deployment Evaluation Cycle..."
Invoke-WmiMethod -ComputerName $systems -Namespace root\ccm -Class sms_client -Name TriggerSchedule -ArgumentList '{00000000-0000-0000-0000-000000000108}' -ErrorAction Stop
LogWrite "Sleeping for 150 Seconds..."
Start-Sleep -Seconds 150

If ($Error) {
$Error.Clear()
}

WSUS Installation Error Code with Solution

Below are some of the error code with the solution to fix them to make sure our machines are getting patched, will keep updating the error with solution.

Update install error - 0x80070308:-
Solution:-
1. Connect to remote computer CMD
"C:\My Documents\SCCM Tools\PSTools\PsExec.exe" \\MachineName cmd
2. run below commands
REG LOAD HKLM\COMPONENTS C:\Windows\System32\config\COMPONENTS
REG DELETE HKLM\COMPONENTS /V PendingRequired /f
3. Run the scan cycles.
_________________________________________________

Get list of Patches installed on remote Computer using Powershell:-
Get-Hotfix -computername MachineName | Select HotfixID, Description, InstalledOn | Sort-Object InstalledOn
__________________________________________________
Update install error - 0X80070543

Solution:-
1) Click Start, click Run, type dcomcnfg.exe, and then click OK.
2) Click OK if you receive the UAC prompt.
3) In the console tree, expand Component Services, and then expand Computers.
4) Right-click My Computer, then click Properties.
5) Click the Default Properties tab.
6) Select Connect in the Default Authentication Level set to Connect.
7) Select Indentify in the Default Impersonation Level list.
8) Click OK, and then click Yes to confirm the selection.
9) Close Component Services console."
or
Add the below registry remotely on the machine.
REG ADD HKLM\SOFTWARE\Microsoft\Ole /v LegacyAuthenticationLevel /t REG_DWORD /d 2 /f
___________________________________________________

When you find WSUS Server is set to NULL in Windowsupdate.log File perform the below steps to fix the issue
WSUS Server :<NULL>
Solution Add below registry by connecting to registry remotely or with Pxeexec.
REG ADD HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate /v WUServer /t REG_SZ /d http://SUPSERVERNAME:8530 /f
REG ADD HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate /v WUStatusServer /t REG_SZ /d http://SUPSERVERNAME:8530 /f
REG ADD HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU /v UseWUServer /t REG_DWORD /d 1 /f

Create configuration Item for Software Update installation

Create configuration Item to resolve past due will be expired,Waiting for install and pending verification software update deployment issues.
Open SCCM console → Asset and compliance → Compliance settings→ right click on Configuration items and Create New configuration Item.
Capture1
Click Next and add supported platforms as per your requirements.
Capture2
Click Next → on settings page click on new to define a new setting.
Capture3
Capture4
Now Add Discovery script and remediation script.
Discovery script will provide return code 1 if there is any pending updates.
Remediation script will remediate if Discovery script returns 1.
Discovery Script:-
$wmicheck=$null
$wmicheck =Get-WmiObject -namespace root\cimv2 -Class Win32_BIOS -ErrorAction SilentlyContinue
if ($wmicheck)
{
# Get list of all instances of CCM_SoftwareUpdate from root\CCM\ClientSDK for missing updates
$TargetedUpdates= Get-WmiObject -Namespace root\CCM\ClientSDK -Class CCM_SoftwareUpdate -Filter ComplianceState=0
$approvedUpdates= ($TargetedUpdates |Measure-Object).count
$pendingpatches=($TargetedUpdates |Where-Object {$TargetedUpdates.EvaluationState -ne 8} |Measure-Object).count
$rebootpending=($TargetedUpdates |Where-Object {$TargetedUpdates.EvaluationState -eq 8} |Measure-Object).count
if ($pendingpatches -gt 0)
{
Return(1)
}
else {Return(0) }
}
Remediation Script:-
#Resolve past due expired and pending verification issue for software update deployment.#Resolve past due expired and pending verification issue for software update deployment.
$wmicheck=$null$wmicheck =Get-WmiObject  -namespace root\cimv2 -Class Win32_BIOS -ErrorAction SilentlyContinueNew-EventLog -LogName Application -Source SyncStateScript -ErrorAction SilentlyContinueif ($wmicheck){# Get list of all instances of CCM_SoftwareUpdate from root\CCM\ClientSDK for missing updates $TargetedUpdates= Get-WmiObject  -Namespace root\CCM\ClientSDK -Class CCM_SoftwareUpdate -Filter ComplianceState=0$approvedUpdates= ($TargetedUpdates |Measure-Object).count$pendingpatches=($TargetedUpdates |Where-Object {$TargetedUpdates.EvaluationState -ne 8} |Measure-Object).count$rebootpending=($TargetedUpdates |Where-Object {$TargetedUpdates.EvaluationState -eq 8} |Measure-Object).countif ($pendingpatches -gt 0) {  try { $MissingUpdatesReformatted = @($TargetedUpdates | ForEach-Object {if($_.ComplianceState -eq 0){[WMI]$_.__PATH}})  # The following is the invoke of the CCM_SoftwareUpdatesManager.InstallUpdates with our found updates  $InstallReturn = Invoke-WmiMethod  -Class CCM_SoftwareUpdatesManager -Name InstallUpdates -ArgumentList (,$MissingUpdatesReformatted) -Namespace root\ccm\clientsdk     Write-EventLog -LogName Application -Source SyncStateScript -EventId 666 -EntryType Information -Message “Targeted Patches :$approvedUpdates,Pending patches:$pendingpatches,Reboot Pending patches :$rebootpending,initiated $pendingpatches patches for install”  } catch {Write-EventLog -LogName Application -Source SyncStateScript -EventId 667 -EntryType Information -Message “pending patches – $pendingpatches but unable to install them ,please check Further”  }}else {Write-EventLog -LogName Application -Source SyncStateScript -EventId 668 -EntryType Information -Message “Targeted Patches :$approvedUpdates,Pending patches:$pendingpatches,Reboot Pending patches :$rebootpending,Compliant”  }}
First add Discovery script as shown below.
Capture5
Click on Compliance rules and define new rule to fetch return code of the discovery script and remediate through remediation script according to the return code defined in the compliance rule.
Capture2


Add remediation script.
Capture8
Capture9
Click Ok and Then Next to finish the wizard.
Now Create a Confguration baseline and add the already created configuration item to it.
Capture9
Capture10
Capture11
Now click ok and complete baseline creation.
Right click on created baseline and select deploy.
Capture13
Capture15
It has been tested and working fine in my current organisation. If you have any doubt or need help then please comment.
If you don’t want to follow this process then there is an another method to achieve the compliance is to  deploying directly the attached remediation script to the affected machines.
Thanks for reading.

SCCM Baseline to achieve software update compliance

[Resolve software update state unknown, waiting for install, pending verification and past due expired issue]:-

In IT industry many people often asked how to increase their software update compliance and we follows many tasks to achieve the compliance however, in sometimes our task got fail to achieve the goal so that we are scolded by the higher management or by client.
As everybody knows recently we faced Wannacry Ransomeware malware attack as a result  we did many struggle to make 100% compliance of MS released patch to remediate Ransoware malware. Not only for Ransoware but also we face many issues every month after patch released.
One major issue we found that update status is unknown even the patch is required for the server or workstation then we will check Wuaagent.log, scanagent.log, windowsupdate.log and etc, everything looks good but still update status is unknown. In order to achieve this I have created a compliance baseline which will check the state message in WMI and will re-send all state messages to the MP.
Open SCCM console → Asset and compliance→Compilance setting
Right click on Configuration Items and select new.
Type a configuration item name →click Next
Capture.1JPG
Select supported platforms, you can select as per your organisation requirement.
Capture2
On setting click on New
Capture3
Type a name for the setting.
On setting type, Select Script as we are going to apply a powerShell script and data type as string.
Now we will have to add two scripts (a) Discovery script – Which will evaluate on the system to find out whether the system is compliant and non-compliant and according to the result client issue will be remediate as per remediation script.
(b) Remediation script – Which will run if the system is non-compliant
Discovery Script:
$Update=Get-WmiObject -class CCM_StateMsg -namespace root\ccm\StateMsg
if($Update.topictype -eq “500” -and $Update.StateID -eq “0”)
{
return{1};
}
else{return{0}}
Remediation Script:
$newCCMUpdatesStore=New-Object -ComObject Microsoft.CCM.UpdatesStore
$newCCMUpdatesStore.RefreshServerComplianceState()
New-EventLog -LogName Application -Source SyncStateScript -ErrorAction SilentlyContinue
Write-EventLog -LogName Application -Source SyncStateScript -EventId 555 -EntryType Information -Message “Sync State ran successfully”
Capture4
Add the attached discovery script to the discovery field as shown below.
Capture5
Click on Compliance rule → Select New rule to capture output of the script as shown below.

Capture1

Click Ok to return to the previous screen and add remediation script.
Capture7
Now click Ok and then Next to complete the configuration item creation wizard.

Configuration Item has been created, now its a time to create a baseline and deploy it the target collection.
Right Click on Configuration baselines → select Create configuration baseline.
Capture9
Type a name for configuration baseline and add already created Configuration item to it.
Capture10
Capture11
Capture12
Baseline has been created , we have to deploy it to the target collections.
Capture13
Select the following options while deploying. Change the schedule if you want to trigger it asap.
Capture14
Capture15
We have now created baseline for software update compliance state which will show you whether software update is required or not required.
We knows this is not the final solution to resolve the issue, sometimes we found another issues after update deployment that software centre will be showing updates are failed to install,waiting for install,pending verification or past due will be expired state.
This is a biggest challenge for us to recover all systems from this problem therefore,I have created another baseline on following post to resolve software update failed to install,waiting for install,pending verification or past due will be expired issue.

5 SCCM Tools

Client Center  Config uration  Manager Here is one of my favorite SCCM tool and probably the most useful I have ever seen!  Client Cent...